libreswan records
24 published records for vendor libreswan.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 70.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference5
- CWE-20 Improper Input Validation4
- CWE-400 Uncontrolled Resource Consumption3
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2013-7283No exploit | Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact alibreswan · libreswan · CWE-362 | Critical9.3 | — | 1.6% | Jan 9, 2014 |
31Monitor | CVE-2020-1763No exploit | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attackerlibreswan · libreswan · CWE-125 | High7.5 | — | 3.6% | May 12, 2020 |
31Monitor | CVE-2016-5391No exploit | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).libreswan · libreswan · CWE-476 | High7.5 | — | 3.0% | Jun 13, 2017 |
31Monitor | CVE-2019-12312No exploit | In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.libreswan · libreswan · CWE-476 | High7.5 | — | 2.7% | May 24, 2019 |
31Monitor | CVE-2016-5361No exploit | programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of libreswan · libreswan · CWE-20 | High7.5 | — | 2.7% | Jun 16, 2016 |
31Monitor | CVE-2016-3071No exploit | Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.libreswan · libreswan · CWE-20 | High7.5 | — | 2.6% | Apr 18, 2016 |
31Monitor | CVE-2022-23094No exploit | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKElibreswan · libreswan · CWE-476 | High7.5 | — | 2.5% | Jan 14, 2022 |
30Monitor | CVE-2023-2295No exploit | A vulnerability was found in the libreswan library.libreswan · libreswan · CWE-400 | High7.5 | — | 1.6% | May 17, 2023 |
30Monitor | CVE-2023-30570No exploit | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive libreswan · libreswan · CWE-400 | High7.5 | — | 1.2% | May 28, 2023 |
30Monitor | CVE-2026-12413No exploit | IKEv2 Denial of Service via malformed fragmentationlibreswan · libreswan · CWE-193 | High7.5 | — | 0.6% | Jul 2, 2026 |
26Monitor | CVE-2023-23009No exploit | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrlibreswan · libreswan · CWE-400 | Medium6.5 | — | 1.6% | Feb 21, 2023 |
26Monitor | CVE-2023-38710No exploit | An issue was discovered in Libreswan before 4.12.libreswan · libreswan | Medium6.5 | — | 0.8% | Aug 25, 2023 |
26Monitor | CVE-2023-38712No exploit | An issue was discovered in Libreswan 3.x and 4.x before 4.12.libreswan · libreswan · CWE-476 | Medium6.5 | — | 0.8% | Aug 25, 2023 |
26Monitor | CVE-2023-38711No exploit | An issue was discovered in Libreswan before 4.12.libreswan · libreswan · CWE-476 | Medium6.5 | — | 0.8% | Aug 25, 2023 |
26Monitor | CVE-2024-3652No exploit | IKEv1 default AH/ESP responder can cause libreswan to abort and restartlibreswan · libreswan · CWE-404 | Medium6.5 | — | 0.8% | Apr 10, 2024 |
23Monitor | CVE-2026-50721No exploit | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payloadlibreswan · libreswan · CWE-347 | Medium5.9 | — | 0.4% | Jul 2, 2026 |
23Monitor | CVE-2026-50722No exploit | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payloadlibreswan · libreswan · CWE-347 | Medium5.9 | — | 0.3% | Jul 2, 2026 |
21Monitor | CVE-2013-4564No exploit | Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid majlibreswan · libreswan · CWE-189 | Medium5.0 | — | 2.7% | Jan 7, 2014 |
21Monitor | CVE-2015-3204No exploit | libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bitlibreswan · libreswan · CWE-20 | Medium5.0 | — | 2.6% | Jul 1, 2015 |
21Monitor | CVE-2013-7294No exploit | The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (reslibreswan · libreswan · CWE-20 | Medium5.0 | — | 2.5% | Jan 16, 2014 |
21Monitor | CVE-2013-6467No exploit | Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 plibreswan · libreswan | Medium5.0 | — | 2.5% | Jan 26, 2014 |
21Monitor | CVE-2013-2052No exploit | Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allowlibreswan · libreswan · CWE-119 | Medium5.1 | — | 1.8% | Jul 9, 2013 |
18Monitor | CVE-2015-3240No exploit | The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of libreswan · libreswan · CWE-189 | Medium4.3 | — | 2.8% | Nov 9, 2015 |
12Monitor | CVE-2019-10155No exploit | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity libreswan · libreswan · CWE-354 | Low3.1 | — | 0.5% | Jun 12, 2019 |
- CVE-2013-728337Monitor
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact a
CriticalCVSS 9.3No exploitEPSS 2%libreswan · libreswanJan 9, 2014
- CVE-2020-176331Monitor
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker
HighCVSS 7.5No exploitEPSS 4%libreswan · libreswanMay 12, 2020
- CVE-2016-539131Monitor
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
HighCVSS 7.5No exploitEPSS 3%libreswan · libreswanJun 13, 2017
- CVE-2019-1231231Monitor
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
HighCVSS 7.5No exploitEPSS 3%libreswan · libreswanMay 24, 2019
- CVE-2016-536131Monitor
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of
HighCVSS 7.5No exploitEPSS 3%libreswan · libreswanJun 16, 2016
- CVE-2016-307131Monitor
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
HighCVSS 7.5No exploitEPSS 3%libreswan · libreswanApr 18, 2016
- CVE-2022-2309431Monitor
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKE
HighCVSS 7.5No exploitEPSS 3%libreswan · libreswanJan 14, 2022
- CVE-2023-229530Monitor
A vulnerability was found in the libreswan library.
HighCVSS 7.5No exploitEPSS 2%libreswan · libreswanMay 17, 2023
- CVE-2023-3057030Monitor
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive
HighCVSS 7.5No exploitEPSS 1%libreswan · libreswanMay 28, 2023
- CVE-2026-1241330Monitor
IKEv2 Denial of Service via malformed fragmentation
HighCVSS 7.5No exploitEPSS 1%libreswan · libreswanJul 2, 2026
- CVE-2023-2300926Monitor
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorr
MediumCVSS 6.5No exploitEPSS 2%libreswan · libreswanFeb 21, 2023
- CVE-2023-3871026Monitor
An issue was discovered in Libreswan before 4.12.
MediumCVSS 6.5No exploitEPSS 1%libreswan · libreswanAug 25, 2023
- CVE-2023-3871226Monitor
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
MediumCVSS 6.5No exploitEPSS 1%libreswan · libreswanAug 25, 2023
- CVE-2023-3871126Monitor
An issue was discovered in Libreswan before 4.12.
MediumCVSS 6.5No exploitEPSS 1%libreswan · libreswanAug 25, 2023
- CVE-2024-365226Monitor
IKEv1 default AH/ESP responder can cause libreswan to abort and restart
MediumCVSS 6.5No exploitEPSS 1%libreswan · libreswanApr 10, 2024
- CVE-2026-5072123Monitor
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
MediumCVSS 5.9No exploitEPSS 0%libreswan · libreswanJul 2, 2026
- CVE-2026-5072223Monitor
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
MediumCVSS 5.9No exploitEPSS 0%libreswan · libreswanJul 2, 2026
- CVE-2013-456421Monitor
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid maj
MediumCVSS 5.0No exploitEPSS 3%libreswan · libreswanJan 7, 2014
- CVE-2015-320421Monitor
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bit
MediumCVSS 5.0No exploitEPSS 3%libreswan · libreswanJul 1, 2015
- CVE-2013-729421Monitor
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (res
MediumCVSS 5.0No exploitEPSS 3%libreswan · libreswanJan 16, 2014
- CVE-2013-646721Monitor
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 p
MediumCVSS 5.0No exploitEPSS 2%libreswan · libreswanJan 26, 2014
- CVE-2013-205221Monitor
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allow
MediumCVSS 5.1No exploitEPSS 2%libreswan · libreswanJul 9, 2013
- CVE-2015-324018Monitor
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of
MediumCVSS 4.3No exploitEPSS 3%libreswan · libreswanNov 9, 2015
- CVE-2019-1015512Monitor
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity
LowCVSS 3.1No exploitEPSS 1%libreswan · libreswanJun 12, 2019